Back to skill

Security audit

Registry Broker

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do what it advertises, but it sends user messages and API-key-authenticated requests to external services and includes an under-scoped custom endpoint override that could redirect those requests.

Review this before installing in a sensitive environment. Use the default hol.org registry endpoint, avoid setting REGISTRY_BROKER_BASE_URL unless you fully trust the destination, keep the API key scoped and rotatable, and do not send secrets, private prompts, regulated data, or internal-only agent endpoints through chat or registration. Prefer locked local scripts over copy-pasting unversioned npx commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/index.ts:36
Finding

API Key Exposure Through an Unrestricted Custom Base URL

Content
View full analysis

Vulnerability Details

File Location: scripts/index.ts, lines 36–43
Vulnerability Type: Unrestricted credential destination / sensitive information disclosure
Risk Level: Medium

Vulnerable Code

typescript
const DEFAULT_BASE_URL = 'https://hol.org/registry/api/v1';

function getClient(): RegistryBrokerClient {
  return new RegistryBrokerClient({
    baseUrl: process.env.REGISTRY_BROKER_BASE_URL || DEFAULT_BASE_URL,
    apiKey: process.env.REGISTRY_BROKER_API_KEY,
  });
}

Technical Analysis

The application reads both the API destination and the broker API key from environment variables, then supplies them to the same SDK client. REGISTRY_BROKER_BASE_URL is accepted without validating its scheme or hostname.

Consequently, a party capable of influencing this environment variable can redirect authenticated SDK requests to an arbitrary server. Depending on how the SDK implements authentication, the configured REGISTRY_BROKER_API_KEY may be transmitted in an authorization header or another request field to that server.

A custom endpoint is not required for the Skill's declared HOL registry functionality. Allowing an unrestricted destination while automatically reusing the production credential therefore exceeds the minimum privileges needed for that functionality.

This audit did not establish that the default https://hol.org/registry/api/v1 endpoint is malicious. The vulnerability arises when the optional base URL is overridden.

Attack Path

  1. An attacker gains the ability to influence the Skill's process environment, deployment configuration, .env file, or command runner.
  2. The attacker sets REGISTRY_BROKER_BASE_URL to an endpoint under their control, such as https://attacker.example/api.
  3. A legitimate REGISTRY_BROKER_API_KEY remains configured in the environment.
  4. The user or agent invokes a CLI operation such as search_agents, vector_search, `start_conver ...[truncated 1054 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove REGISTRY_BROKER_BASE_URL support if custom API destinations are not essential.
  2. If overrides are required, parse the value with URL and require the https: scheme.
  3. Restrict authenticated requests to an explicit allowlist of trusted hostnames, preferably hol.org and documented service subdomains only.
  4. Do not automatically attach REGISTRY_BROKER_API_KEY to non-default origins. Require a separate credential variable for custom endpoints.
  5. Reject URLs containing embedded credentials, unexpected ports, IP-literal hosts, loopback addresses, link-local addresses, or private-network destinations unless explicitly required.
  6. Display a clear warning or require explicit confirmation before sending chat messages, profiles, or credentials to a non-default endpoint.
  7. Apply least-privilege scopes and rotation procedures to broker API keys.
  8. Add automated tests confirming that untrusted schemes and hosts are rejected and that the production key is never attached to custom origins.

Example hardening approach:

typescript
const DEFAULT_BASE_URL = new URL('https://hol.org/registry/api/v1');
const configuredUrl = new URL(
  process.env.REGISTRY_BROKER_BASE_URL || DEFAULT_BASE_URL.href
);

if (
  configuredUrl.protocol !== 'https:' ||
  configuredUrl.hostname !== 'hol.org'
) {
  throw new Error('Untrusted Registry Broker base URL');
}

const client = new RegistryBrokerClient({
  baseUrl: configuredUrl.href,
  apiKey: process.env.REGISTRY_BROKER_API_KEY,
});
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

The code aligns partially with the declared search/exploration capability: it queries the registry broker for stats, registries, protocols, and search results. However, it does not implement any functionality for chatting with agents or registering an agent. Its actual scope is limited to ecosystem exploration and search, making the declared description materially broader than the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a multi-function skill with agent discovery/search, agent-to-agent chat, and registration capabilities. However, the provided code chunk is a single registration example that constructs an agent profile and calls client.registerAgent(). There is no code for searching 72,000+ agents, querying 14 registries, or chatting with agents. While registration is consistent with part of the description, the actual code does not substantiate the broader declared purpose, so the description overstates the implemented behavior for this code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
npx tsx examples/explore-ecosystem.ts

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
npx tsx examples/search-and-chat.ts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · examples/search-and-chat.ts (reported line 69)May include surrounding context.

ts
console.log(`  Chat error: ${e instanceof Error ? e.message : e}`);
    }
  } else {
    console.log('\nℹ️  Add REGISTRY_BROKER_API_KEY to .env to enable chat');
    console.log('   Get your key at https://hol.org/registry');
  }
}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · pnpm-lock.yaml (reported line 704)May include surrounding context.

yaml
resolution: {integrity: sha512-6xx/NmEc84HX7QmsjSC3hHredQYjHv4Dkf4G27adAPf+qN+vnPxmQ7gaTnk243a0++DOFTbZ2gKX/15G2B6SRg==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

  '@libp2p/interface-keychain@2.0.5':
    resolution: {integrity: sha512-mb7QNgn9fIvC7CaJCi06GJ+a6DN6RVT9TmEi0NmedZGATeCArPeWWG7r7IfxNVXb9cVOOE1RzV1swK0ZxEJF9Q==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · pnpm-lock.yaml (reported line 5402)May include surrounding context.

yaml
resolution: {integrity: sha512-6xx/NmEc84HX7QmsjSC3hHredQYjHv4Dkf4G27adAPf+qN+vnPxmQ7gaTnk243a0++DOFTbZ2gKX/15G2B6SRg==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

  '@libp2p/interface-keychain@2.0.5':
    resolution: {integrity: sha512-mb7QNgn9fIvC7CaJCi06GJ+a6DN6RVT9TmEi0NmedZGATeCArPeWWG7r7IfxNVXb9cVOOE1RzV1swK0ZxEJF9Q==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · pnpm-lock.yaml (reported line 9148)May include surrounding context.

yaml
resolution: {integrity: sha512-6xx/NmEc84HX7QmsjSC3hHredQYjHv4Dkf4G27adAPf+qN+vnPxmQ7gaTnk243a0++DOFTbZ2gKX/15G2B6SRg==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

  '@libp2p/interface-keychain@2.0.5':
    resolution: {integrity: sha512-mb7QNgn9fIvC7CaJCi06GJ+a6DN6RVT9TmEi0NmedZGATeCArPeWWG7r7IfxNVXb9cVOOE1RzV1swK0ZxEJF9Q==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README encourages users to search agents, start conversations, and register agents via external registry and agent services, but it does not warn that prompts, session content, profile data, and endpoints may be transmitted to third-party systems. In a skill specifically designed to broker communication across many external registries and agents, this omission can cause users to disclose sensitive data under the false assumption that interactions remain local or trusted.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares an environment dependency (REGISTRY_BROKER_API_KEY) but does not define any explicit tool scope or permission boundary. In agent ecosystems, missing scope declarations can cause the runtime or user to underestimate that the skill consumes sensitive configuration and makes authenticated external requests, increasing the risk of unintended secret exposure or over-broad execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation encourages starting chats with third-party agents and registering agents through external services without warning that prompts, metadata, URLs, session IDs, and possibly credentials-related context will be transmitted off-platform. In this skill context, that is materially risky because the core feature is cross-registry discovery and messaging with many external agents of varying trust levels, so users may unintentionally disclose sensitive data to third parties.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Using npx tsx without pinning an exact version allows resolution of whatever package version is current in the registry or local environment at execution time. This creates a supply-chain risk where a compromised, malicious, or breaking package release could be fetched and executed, leading to arbitrary code execution in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This command again relies on unpinned npx tsx, which can fetch or execute an unexpected version at runtime. In an agent skill context, that exposes the host to supply-chain compromise before any of the documented registry operations occur.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The documented flow uses npx tsx without version pinning, preserving the same package substitution and remote execution risk. Because these examples are meant to be copy-pasted by users, they normalize unsafe execution practices that may run arbitrary package code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This instance repeats the unpinned npx tsx pattern, exposing users to execution of unreviewed dependency versions. The danger is amplified because the command may run in environments that also hold API keys needed for authenticated registry operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Another copy-pasteable command uses unpinned npx tsx, creating avoidable supply-chain exposure. If a malicious package version were served, it could read environment variables, alter requests, or exfiltrate data before invoking the intended script.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The registration example also depends on unpinned npx tsx, so executing the documented command can run arbitrary package code with access to registration payloads and any configured API key. That creates a realistic path for credential theft or tampering with outbound registration requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This example command continues the same unsafe pattern of executing unpinned npx tsx. Repetition across the document increases the chance that users adopt the insecure practice broadly, multiplying supply-chain attack surface.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Unpinned npx tsx here presents the same supply-chain risk as elsewhere in the file. Since the command is intended for search/chat workflows, any compromise could also intercept user prompts or conversation data sent through the tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The final example likewise uses unpinned npx tsx, leaving execution behavior dependent on external package state. This is dangerous because the registration workflow may involve trusted metadata, URLs, and credentials that could be modified or exfiltrated by a compromised package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The example instructs users to run the script via npx tsx, which can fetch and execute a package version that is not explicitly pinned. This creates a supply-chain risk: if the resolved version is compromised or unexpectedly changes, users may execute attacker-controlled code during example usage.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The example instructs users to run the script via npx tsx, which can fetch and execute a package version that is not explicitly pinned. If a malicious or compromised tsx release is resolved at execution time, arbitrary code could run on the user's machine during a registry-registration workflow that likely has access to API keys and local environment variables.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The shebang uses #!/usr/bin/env npx tsx, which allows npx to resolve and execute whatever tsx version is available at runtime rather than a pinned, audited version. This creates supply-chain risk: a compromised or unexpected package version could execute arbitrary code whenever the script is launched.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.